An Ontario family law firm engaged LeakTrace after an administrator intercepted a client-directed wire redirect attempt during the settlement phase of a matrimonial matter. The audit identified the reconnaissance pattern the fraud attempt was built on and closed the exposure conditions the pattern had exploited.
Engagement origin
The firm operates a boutique family law practice with several partners and support staff in one Ontario location. During the settlement phase of a matrimonial matter, the firm's administrator received a wire instruction claiming to originate from a client with a plausible pretext consistent with the settlement schedule. The administrator identified an authentication inconsistency and escalated to the managing partner rather than executing the wire. The wire was not executed. The managing partner engaged LeakTrace to determine how the attempted fraud had constructed its pretext and to identify any adjacent exposure conditions the firm should close before repeating the settlement workflow.
Discovery scope
LeakTrace conducted a seventy-two-hour external attack surface audit covering the firm's registered domain, partner and administrator email patterns, the firm's public web presence, the vendor mapping visible through DNS, and public-record aggregation associated with the specific client's matter to the extent that public records disclosed. The engagement did not touch the firm's internal systems, did not access any client file, and did not require any communication with the client whose matter was affected.
Findings summary
- Administrator email breach exposure. The administrator's business email address appeared in a monitored breach database from a widely-reported incident affecting a common business services platform. The breach index disclosed the address and a hashed password fragment, and the same login pattern was reused across the firm's document management system access.
- Public court records disclosure. Ontario court records disclosed the matter number, party names, and a settlement conference date consistent with the timeline of the attempted wire redirect. The attempted fraud's pretext referenced elements identifiable in the public court record, indicating the adversary had used public court disclosure rather than internal firm access to construct the pretext.
- Firm domain authentication gaps. The firm's Sender Policy Framework and Domain-based Message Authentication configuration did not block a well-formed spoofing attempt originating from an external mail server, meaning the attempted wire instruction had been able to present a display name consistent with the client's contact pattern without triggering authentication warnings on the administrator's mail client.
- Vendor mapping through DNS. DNS records disclosed the firm's mail infrastructure vendor and its document management platform, both of which had been referenced in the attempted fraud's pretext language, indicating the adversary had used the vendor mapping to make the pretext internally consistent.
Firm actions
The firm executed a remediation program within the two weeks following findings delivery. The administrator's credentials were rotated across all business accounts, multi-factor authentication was enforced on the document management platform, and the reuse pattern was addressed with a passphrase manager rolled out to all staff. Sender Policy Framework and Domain-based Message Authentication configurations were revised to block spoofing attempts. Wire authorization workflow was revised to require an out-of-band voice confirmation on any wire instruction associated with a client matter, using contact numbers held in the client intake record rather than provided in the wire instruction. The firm briefed its clients on the revised authorization workflow at the settlement conference phase of subsequent matters.
Outcome
The firm did not receive any subsequent wire redirect attempts consistent with the identified pattern in the following twelve months. The Law Society continuing professional development materials the firm's managing partner subsequently contributed to referenced the pattern as a documented example of family law wire-fraud reconnaissance, without identifying the specific matter or client. The firm engaged LeakTrace for continuous monitoring across the firm's external exposure with reporting on a quarterly cadence.
All findings were derived from public and monitored sources only. No portion of this engagement required access to the firm's internal systems, any client file, or coordination with any threat actor. Public court record analysis used only Ontario Superior Court and Family Court public disclosures. This case file documents the pattern of post-attempt wire-fraud reconnaissance engagements LeakTrace conducts with Ontario family law firms, and is not attributed to the specific firm, client, or matter referenced.